Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43999
Total
3569
Critical
13202
High
13005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47626 | HIGH | 8.2 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit … | Aug 25, 2026 |
| CVE-2026-47624 | MEDIUM | 6.0 | NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability … | Aug 25, 2026 |
| CVE-2026-24263 | HIGH | 8.2 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful … | Aug 25, 2026 |
| CVE-2026-24262 | HIGH | 8.2 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit … | Aug 25, 2026 |
| CVE-2026-24225 | MEDIUM | 6.0 | NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit … | Aug 25, 2026 |
| CVE-2026-24170 | HIGH | 8.8 | NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP … | Aug 25, 2026 |
| CVE-2026-24169 | HIGH | 8.0 | NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially … | Aug 25, 2026 |
| CVE-2026-24168 | MEDIUM | 6.8 | NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API … | Aug 25, 2026 |
| CVE-2026-24167 | MEDIUM | 6.8 | NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A … | Aug 25, 2026 |
| CVE-2026-24166 | MEDIUM | 5.1 | NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful … | Aug 25, 2026 |
| CVE-2026-19913 | HIGH | 7.5 | The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter … | Aug 25, 2026 |
| CVE-2026-19912 | UNKNOWN | — | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php … | Aug 25, 2026 |
| CVE-2026-18445 | MEDIUM | 6.6 | There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code … | Aug 25, 2026 |
| CVE-2026-18444 | MEDIUM | 6.6 | There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure … | Aug 25, 2026 |
| CVE-2026-16234 | HIGH | 7.8 | There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an … | Aug 25, 2026 |
| CVE-2026-16233 | HIGH | 7.8 | There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an … | Aug 25, 2026 |
| CVE-2026-13478 | MEDIUM | 5.5 | The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) … | Aug 25, 2026 |
| CVE-2026-13217 | MEDIUM | 5.9 | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code … | Aug 25, 2026 |
| CVE-2026-13216 | MEDIUM | 6.1 | The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI … | Aug 25, 2026 |
| CVE-2026-79785 | MEDIUM | 5.9 | X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain … | Aug 25, 2026 |
| CVE-2026-79784 | HIGH | 8.8 | Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the … | Aug 25, 2026 |
| CVE-2026-79783 | LOW | 3.6 | rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on … | Aug 25, 2026 |
| CVE-2026-79782 | LOW | 3.1 | rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can … | Aug 25, 2026 |
| CVE-2026-79781 | MEDIUM | 6.5 | rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 … | Aug 25, 2026 |
| CVE-2026-79780 | MEDIUM | 5.3 | rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme … | Aug 25, 2026 |